MALICIOUS — e59a45f900fdf1448453e0a2a0a1b1e83f30db27a576caae708afc4905c5deab
MALICIOUS — e59a45f900fdf1448453e0a2a0a1b1e83f30db27a576caae708afc4905c5deab is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e59a45f900fdf1448453e0a2a0a1b1e83f30db27a576caae708afc4905c5deab - SHA-1:
51d91279070106f4543faeb0ac50d50ea536022c - MD5:
ea48ff7886914aec8d30b2f03360e743 - ssdeep:
1536:WvMTrm+ruznZPDvY/5KgiJ890tNTVDOBpEBIxvHsXY8N5djLUJ+1p7SJ:uMPm5nZbv8M+0LTVkPsI8HdcE1p4 - TLSH:
T18138C0F311D3EC4CBE96AB076DBA241DA0C9C6886125876445C4BB6DC0BC7EEBE10991 - Submitted as: e59a45f900fdf1448453e0a2a0a1b1e83f30db27a576caae708afc4905c5deab
- File type: pdf · Size: 77736 bytes
- Verdict: malicious (98/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/42a8acec-34a3-4900-abf1-48f363ec07dd/12904799008.pdf - network signal, weight 0.70, confidence 0.80
- Contacted 14 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://queure.ru/pbw?utm_term=pirates+of+the+caribbean+tamil+dubbed+full+movie+watch+online, https://uploads.strikinglycdn.com/files/42a8acec-34a3-4900-abf1-48f363ec07dd/12904799008.pdf, http://mupalunava.pbworks.com/f/quadratic_equation_questions_for_sbi_clerk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9675 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787877093&P2=404&P3=2&P4=dCcz0QmCP0bjrETWUTIknOz7JpY64iyH3Jz7AOupa0pjou6KSO%2f9zDsekAmbBTtAvC5bgvS4sjNkHJEn7iyJsQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787877126&P2=404&P3=2&P4=lM7U6kblzjmEoVx9FDKaFcesH0ws%2fV9y1HKdxkodr5Kva48iEenYfJwxrUj0f5vgUeRbWerlOOzIzoMKVrqo1w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787273779&P2=404&P3=2&P4=K84vA%2fMs4X7lIcP3I%2bD40E%2bl64t5nn0Kn98I8A%2b6opTChYdBsLrLM%2fMy1hfqQbYsltC7rFsWRoaELvJXJNO0BQ%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\SumatraPDF\SumatraPDF-settings.txt -
c1280b0dc1c2aa41cfba33a2db2e8e3ffd432b3640ac2cb44429d86fa0244880 - C:\Users\analyst\AppData\Local\SumatraPDF\sumatrapdfcache\a1617bab752d5e78f530cd8f4cf00cae.png -
7dba0eb82cd32ff747477e6a09131ab5677f8ac9136cf7244831c0014d34247c - root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://queure.ru/pbw?utm_term=pirates+of+the+caribbean+tamil+dubbed+full+movie+watch+online
- https://uploads.strikinglycdn.com/files/42a8acec-34a3-4900-abf1-48f363ec07dd/12904799008.pdf
- http://mupalunava.pbworks.com/f/quadratic_equation_questions_for_sbi_clerk.pdf
- http://mawasuwov.pbworks.com/w/file/fetch/144556701/bhishma_full_movie_in_hindi_dubbed_download_filmywap.pdf
- http://zizovitunex.pbworks.com/w/file/fetch/144487014/82217638336.pdf
- http://sakulibur.pbworks.com/f/fakapuvedugexudox.pdf
- http://berilizi.pbworks.com/w/file/fetch/144823482/58806411726.pdf
- http://xifilipisi.pbworks.com/w/file/fetch/144683037/coleman_lantern_travel_trailer_parts.pdf
- https://logudapixifoke.weebly.com/uploads/1/3/4/3/134371583/6104f69822.pdf
- http://kuzimotum.pbworks.com/w/file/fetch/144823269/first_aid_basic_sciences.pdf
- https://uploads.strikinglycdn.com/files/9c0c3f0d-f665-4916-ae16-bb1331384b8a/application_format_for_school_teacher_job_in_hindi.pdf
- http://nusuwoxub.pbworks.com/w/file/fetch/144426261/angular_custom_form_control_ngmodel.pdf
- http://dujimowiwup.pbworks.com/f/what_does_ra_look_like_the_egyptian_god.pdf
- http://fisagibop.pbworks.com/w/file/fetch/144779820/xafugavodulabajonabipem.pdf
- http://lebunurivugu.pbworks.com/w/file/fetch/144439776/family_tree_printable.pdf
- http://volikedejefa.pbworks.com/w/file/fetch/144811926/76370650918.pdf
- https://uploads.strikinglycdn.com/files/33c7c716-3064-4b95-92a1-3db7896c36ec/how_to_change_solenoid_cub_cadet_lt1045.pdf
- http://wuwolufit.pbworks.com/f/is_pumpkin_a_veg_or_fruit.pdf
- http://tefuraviwuw.pbworks.com/f/nufizevivaliwexapuguzozex.pdf
- https://nabesoke.weebly.com/uploads/1/3/4/0/134042749/310058.pdf
- https://uploads.strikinglycdn.com/files/ce0af812-8ec3-4e71-9dae-bdf8e0a09604/69675194424.pdf
- http://xobapotowi.pbworks.com/f/rilimububopafaxezokura.pdf
- http://lakebimutep.pbworks.com/f/motijajefore.pdf
- https://uploads.strikinglycdn.com/files/056e4e9f-c3f5-481e-b51b-d8a5b18d5252/75488198992.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- queure.ru
- uploads.strikinglycdn.com
- mupalunava.pbworks.com
- mawasuwov.pbworks.com
- zizovitunex.pbworks.com
- sakulibur.pbworks.com
- berilizi.pbworks.com
- xifilipisi.pbworks.com
- logudapixifoke.weebly.com
- kuzimotum.pbworks.com
- nusuwoxub.pbworks.com
- dujimowiwup.pbworks.com
- fisagibop.pbworks.com
- lebunurivugu.pbworks.com
- volikedejefa.pbworks.com
- wuwolufit.pbworks.com
- tefuraviwuw.pbworks.com
- nabesoke.weebly.com
- xobapotowi.pbworks.com
- lakebimutep.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 4.150.223.96
- 52.110.12.24
- 20.247.184.197
- 4.230.171.124
- 40.84.97.4
- 74.178.240.51
- 52.123.128.14
- 52.123.129.14
- 20.184.175.10
- 74.178.240.61
- 135.233.95.80
- 203.26.79.13
- 13.89.179.15
- 20.184.175.3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report